Twenty-two documents and three workbooks covering the documented information ISO 22301:2019 requires, each one carrying both the ISO clauses it satisfies and the DORA articles it evidences at the same time. Plus the instrument that tells you what would fail a Stage 1 review.
We are not a certification body. Certification against ISO 22301:2019 is granted only by an accredited certification body, after a Stage 1 documentation review and a Stage 2 implementation audit. This pack prepares the documents you present at those audits. No document set can make you certified, and any vendor implying otherwise is selling you something they cannot deliver. What we can do is make sure the documentation is not the thing that fails.
A financial entity subject to DORA has already written a continuity policy, run an impact analysis, tested its plans and reported to its board. ISO 22301 asks for the same substance in a different shape. Building the two separately is the default, and it is pure waste.
Every document opens with two tables: the ISO clauses it satisfies, and the DORA articles and technical standards it evidences at the same time. Nobody else sells an ISO 22301 pack that is simultaneously a DORA evidence set, because nobody else builds ISO documentation for this audience.
| What is in the pack | ||
|---|---|---|
| 01 | How to use this toolkit and implementation roadmap | orientation |
| 02 | BCMS manual | 4.1, 4.4, 8.1 |
| 03 | BCMS scope statement and boundaries | 4.3 |
| 04 | Business continuity policy | 5.2 |
| 05 | Roles, responsibilities and authorities | 5.3, 7.1 |
| 06 | Business continuity objectives and the plan to achieve them | 6.2 |
| 07 | Competence, awareness and training programme | 7.2, 7.3 |
| 08 | BCMS communication procedure | 7.4 |
| 09 | Control of documented information procedure | 7.5 |
| 10 | Business impact analysis and risk assessment procedure | 8.2 |
| 11 | Business continuity strategies and solutions | 8.3 |
| 12 | Incident response structure and activation procedure | 8.4.2 |
| 13 | Warning and communication procedure | 8.4.3 |
| 14 | Business continuity plan template | 8.4.4 |
| 15 | ICT disaster recovery plan template | 8.4.4, 8.4.5 |
| 16 | Crisis management team charter | 8.4.2 |
| 17 | Exercise, evaluation and improvement programme | 8.5, 8.6 |
| 18 | Exercise plan and post-exercise report template | 8.5 |
| 19 | Monitoring, measurement and evaluation procedure | 9.1 |
| 20 | Internal audit programme and procedure | 9.2 |
| 21 | Management review procedure and agenda pack | 9.3 |
| 22 | Nonconformity and corrective action procedure | 10.1, 10.2 |
| 23 | Certification readiness workbook (Excel) | the instrument |
| 24 | BCMS registers workbook (Excel) | 4.2.2, 6.1, 8.2.3 |
| 25 | Records and evidence workbook (Excel) | every retain clause |
Secure payment by Stripe. VAT invoice issued automatically; EU businesses entering a VAT number get the reverse-charge invoice.
A folder of templates tells you what to write. It does not tell you whether you are ready, or what an auditor is about to ask. This one does both.
Mandatory documented information that is not yet approved fails a Stage 1 documentation review. The workbook marks each one, so you clear them before you book a certification body rather than after they have invoiced you.
Every requirement carries the literal Stage 2 question, in the auditor's own framing. The internal audit checklist is generated from the same wording, so auditing yourself rehearses the real thing.
Already certified to ISO/IEC 27001 or ISO 9001? One answer on the Setup tab marks 20 shared management-system clauses as reusable evidence rather than new work.
We deliberately do not ship the same file under two products. If you own these, this pack complements them rather than repeating them.
That toolkit measures your ISO 22301 maturity. This one builds the documentation. No assessment content is duplicated here.
See the assessment toolkits →Clause 8.2.2 asks for a BIA. This pack ships the procedure; the BIA workbook is the instrument that produces the output.
See the BIA Toolkit →That pack's ICT continuity policy is anchored on DORA Articles 11 and 12. Document 04 here is the organisation-wide BCMS policy clause 5.2 asks for. Different altitude, both stand alone.
See the premium library →No. Certification is granted only by an accredited certification body after a Stage 1 and a Stage 2 audit. This pack prepares the documentation you present there and tells you when it is ready. Documentation is the part of a certification project that is predictable; implementation and evidence are yours.
No, and holding the certificate does not make you DORA compliant. The two overlap heavily in substance and not at all in form: DORA is supervised, ISO is certified. What overlaps is the evidence, which is why every document here is mapped both ways.
Roughly twenty of the fifty-two requirements are shared management-system clauses — context, leadership, planning, support, performance evaluation and improvement. Set that flag on the readiness workbook and it marks them as reusable evidence. The genuinely new work is clause 8: impact analysis, strategies, plans, response structure and exercising.
Some advertise more files. Count what they are: many packs pad the number with one-page forms. We ship 22 documents, 3 workbooks and roughly 180 pages, we list every one of them above with the clause it satisfies, and we include an instrument none of them have. Compare the list, not the number.
Yes. It is licensed to one named purchaser and there is no per-engagement fee. Save a copy per client and replace the placeholders.
The clause structure lives in one place in our build, so a revision is a rebuild rather than a rewrite of twenty-two documents. Updated editions are emailed to purchasers.
Yes. ISO 22301:2019 is copyrighted and we do not reproduce its text or its tables. You will need a licensed copy, and your certification body will expect you to have one.
Take our free 5-minute assessment and get an instant DORA compliance score with personalised recommendations.